September 10, 2026
BlueMoon exploit kit chains Chrome and Windows zero-days within days of patch publication, with four suspected China-linked espionage groups weaponizing the same toolkit on US and Southeast Asian targets from late August onward. Cisco Secure Firewall Management Center CVEs are under active exploitation by three distinct post-compromise clusters including a ransomware operator and Sandworm-attributed activity. DeepSeek AI agent harness contained an authentication bypass allowing remote agents to escalate privileges via a single shell command; Anthropic declined to provide pre-release model access to UK authorities, triggering debate over AI protectionism. Stealer logs now monetize replayable AI-service tokens from compromised systems, with over 500 valid Google, Anthropic, and Cursor credentials found in a single 7 GB dump.
August 21, 2026
Microsoft's Defender Boot-Time Removal driver (BTR.sys) can be weaponized as a Ring-0 primitive to bypass Tamper Protection and delete EDR/AV before they start, with no vulnerability or BYOVD required. Zimbra, GitLab, and MLflow are actively exploited in the wild, while OpenAI paused frontier RL training after the Hugging Face breach and deployed Astra autonomous agents. Citrix NetScaler CVE-2026-19490 is a critical authentication bypass expected to be exploited imminently, and a Rust supply-chain attack deployed malicious proc-macro crates with PowerShell backdoors targeting Windows build systems.
August 8, 2026
OpenAI halted development of its Astra model after determining it may have reached the "Critical" cybersecurity risk tier, capable of autonomously developing zero-day exploits against hardened systems. An actively exploited N-able N-central vulnerability has now reached customer networks, with ransomware crews confirmed to be wielding the exploit. WordPress patched CVE-2026-64638, a pre-auth reflected XSS flaw that chains to RCE affecting all versions. Google Mandiant attributed a 200+ organization extortion campaign to UNC6671, which rebranded from BlackFile and targeted major financial institutions including Blackstone, KKR, and Apollo.
July 17, 2026
- OpenSSL "HollowByte" is a remote DoS triggered by an 11-byte malformed TLS header that drives memory exhaustion and server lockup; fixed in v4.0.1 and backports (Okta Security).
· Vulnerabilities & Exploits
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
July 11, 2026
- Okta is warning of vishing attacks (tracked as O-UNC-066) that call Microsoft 365 users and walk them through enrolling a fresh Entra ID passkey via a panel-controlled phishing kit mirroring the Entra login flow — establishing durable, phish-resistant-looking access for data extortion. The Hacker News, SecurityWeek
· Cloud & Identity
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat